Price-Sensitive Info · 8 min read

Understanding the Structured Digital Database SEBI Mandate for Investors

Short answer

The structured digital database SEBI requirement is a mandatory digital log maintained by listed companies to track the flow of Unpublished Price Sensitive Information (UPSI). Under Regulation 3(5) of the SEBI (Prohibition of Insider Trading) Regulations, 2015, it ensures an immutable audit trail of who shared sensitive data and with whom, preventing market leaks.

Understanding the Structured Digital Database SEBI Mandate for Investors

Key takeaways

  • The Structured Digital Database (SDD) is an internal, non-tamperable digital record used to prevent insider trading by tracking sensitive information flow.
  • Under the 2025 amendment, companies must log external UPSI within two calendar days of receipt.
  • Non-compliant companies are publicly flagged by stock exchanges with a specific tag on their quote pages.

The Core Framework of the Structured Digital Database SEBI Rules

The Indian stock market operates on the fundamental principle of information parity, where every investor should have access to price-moving news at the same time. To enforce this, the Securities and Exchange Board of India (SEBI) introduced the requirement for a Structured Digital Database (SDD). This mandate is primarily governed by the SEBI (Prohibition of Insider Trading) Regulations, 2015, specifically under Regulation 3(5) and 3(6).

The SDD is not merely a file or a folder; it is a sophisticated compliance tool that records every instance where Unpublished Price Sensitive Information (UPSI) is shared. Whenever a company discusses potential dividends, mergers, or financial results before they are public, they must log who shared the information and who received it. This creates a digital 'paper trail' that SEBI can audit if they notice suspicious price movements before a formal announcement.

By requiring an immutable record, the regulator aims to deter individuals from leaking confidential data to friends or associates, as the source of the leak can now be pinpointed with digital precision. This framework has evolved significantly since its inception, moving from a general guideline to a strict technical requirement that leaves no room for manual manipulation.

Why the Structured Digital Database SEBI Requirement is an Anti-Leak Mechanism

Before the structured digital database SEBI mandate, tracking the source of an information leak was an arduous task for investigators. If a stock price surged 10% on high volume just hours before a major merger announcement, SEBI had to rely on phone records and interviews to find the culprit. Today, the SDD acts as a preventative shield.

The knowledge that their name is being logged into a permanent, time-stamped database prevents 'designated persons'—such as directors, employees, and key managerial personnel—from sharing tips. The database must be maintained internally by the company, ensuring that the Board of Directors remains responsible for its integrity. According to SEBI Regulation 3(5), this database must contain the names of persons with whom information is shared along with their Permanent Account Number (PAN) or any other identifier authorized by law.

This level of granular detail makes it nearly impossible for an insider to claim they were not part of the information chain. For the retail investor, this means a fairer playing field. When companies follow these rules, it reduces the frequency of 'front-running' and 'insider trading,' ensuring that the price you pay for a share isn't being manipulated by someone with an unfair information advantage.

Want this tracked for you?

ALFA Finder watches every NSE & BSE filing 24/7 and alerts you the moment one matters.

Start Free Today 15-day trial

UPSI Classifications and the 2025 Regulatory Expansion

Category of InformationPrevious Framework (Pre-2025)Expanded Framework (Effective June 2025)
Number of UPSI Categories5 Illustrative Categories16 Detailed Categories
AlignmentStand-alone PIT definitionsAligned with Regulation 30 of LODR
External Info EntryNo specific time limit mentionedMandatory entry within 2 calendar days
Materiality ThresholdSubjective interpretationStrictly defined by financial impact

Key Compliance Requirements and Technical Standards

  • The database must have an internal time-stamping mechanism that cannot be altered or bypassed by the user.
  • Excel spreadsheets and Word documents are strictly non-compliant as they lack a non-tamperable audit trail (Source: SEBI FAQs).
  • Data preservation is mandatory for a minimum period of 8 years after the completion of the relevant transaction or event.
  • Listed entities must submit an SDD Compliance Certificate within 60 days from the end of the financial year to the exchanges.
  • The responsibility for making entries lies with the Designated Persons (DPs) sharing the information, not just the Compliance Officer.
  • Fiduciaries such as law firms, CA firms, and merchant bankers must maintain their own independent SDD systems.
  • Non-compliant companies are tagged as 'NON-COMPLIANT WITH SDD' on the BSE and NSE 'Get Quote' pages for public visibility.

The Evolution of UPSI and the 2025 Amendment Impact

On March 11, 2025, SEBI notified the SEBI (Prohibition of Insider Trading) (Amendment) Regulations, 2025, which comes into effect on June 9, 2025. This is perhaps the most significant update to the SDD regime in years. Previously, the definition of what constituted Unpublished Price Sensitive Information (UPSI) was somewhat narrow, covering five main areas like financial results and dividends.

The 2025 amendment has expanded this to 16 categories, effectively synchronizing PIT regulations with the materiality thresholds of SEBI (LODR) Regulations. For investors, this means a much wider range of corporate actions—such as major product launches, regulatory approvals, or forensic audits—must now be logged in the SDD. Furthermore, a new '2-calendar-day' rule has been introduced for external information.

If a company receives a sensitive letter from a regulator or a major legal notice, they no longer have an indefinite window to log it; it must be in the database within 48 hours. This expansion significantly tightens the net around potential leaks. Using a platform like ALFA Finder can help investors stay ahead of these developments by monitoring when companies make formal announcements related to these expanded categories, allowing for a better understanding of which events were likely tracked under the SDD framework before they hit the public domain.

How to Verify a Company's SDD Compliance Status

  1. 1 Visit the official website of the National Stock Exchange (NSE) or Bombay Stock Exchange (BSE).
  2. 2 Search for the specific company using its name or ticker symbol to reach the 'Get Quote' page.
  3. 3 Look for a tag or label indicating 'NON-COMPLIANT WITH SDD'—this is a red flag for corporate governance.
  4. 4 For deeper research, navigate to the 'Corporate Filings' or 'Announcements' section.
  5. 5 On NSE, follow the path: NEAPS > COMPLIANCE > Announcements > Announcements/CA and look for the subject 'Structural Digital Database'.
  6. 6 On BSE, check the 'Listing Compliance' module for the Structured Digital Database Compliance Certificate.
  7. 7 Review the annual reports to ensure the Secretarial Audit report mentions compliance with PIT Regulation 3(5).

Fiduciaries, Intermediaries, and the Wider SDD Ecosystem

A common misconception is that only the listed company needs to maintain a structured digital database. In reality, the law extends to every entity that handles UPSI. This includes fiduciaries like law firms, accounting firms, and merchant bankers, as well as intermediaries like brokers and AMCs.

For instance, the 2022 amendment, which became effective on July 25, 2024, specifically brought 'units of mutual funds' under the PIT umbrella. This means Asset Management Companies (AMCs) must now maintain an SDD for sensitive information regarding their fund schemes. If a law firm is drafting a merger agreement for two NSE-listed companies, that law firm must have its own internal SDD to track which of its partners and associates have access to the draft.

This decentralized but mandatory record-keeping ensures that if a leak occurs, SEBI can trace it through the entire ecosystem—from the company to the lawyers, and from the lawyers to the bankers. For a retail investor, this comprehensive oversight reduces the 'information leakage' that often happens in the service industry surrounding big corporate deals. By using advanced event intelligence tools like ALFA Finder, investors can track the speed and frequency of these corporate actions, gaining insight into how well a company manages its disclosure obligations in real-time.

The Consequences of Non-Compliance for Shareholders

When a company fails to maintain a compliant structured digital database, the consequences are both regulatory and reputational. For the entity, it can lead to hefty penalties and being barred from the capital markets. For the shareholders, the impact is often felt in the form of increased volatility and a 'governance discount' on the stock price.

Institutional investors are often hesitant to invest in companies that are flagged as non-compliant by the exchanges. According to the NSE and BSE circulars dated October 18, 2024, companies marked as non-compliant must submit their SDD certificates on a quarterly basis, rather than annually, until they demonstrate full adherence to the rules. This 'probation' period serves as a warning to the market.

As an investor, seeing a company repeatedly fail its SDD compliance checks should be a signal to dig deeper into its internal controls. While the SDD is an internal tool that you cannot see directly, the certificates and the exchange tags are public signals. A company that cannot manage its internal data flow is often a company that may have broader transparency issues.

Monitoring these compliance filings is as essential as reading a balance sheet for any serious long-term investor in the Indian market.

Frequently asked questions

Can a company use an Excel sheet for SDD compliance?

No, Excel spreadsheets are not compliant with SEBI regulations. The database must have a non-tamperable audit trail and automatic time-stamping, features that standard spreadsheets lack. Regulation 3(5) requires a system where entries cannot be modified or deleted once made.

What happens if a company is marked 'NON-COMPLIANT WITH SDD'?

If a company is marked non-compliant, it is publicly tagged on the stock exchange website, alerting all investors to a governance risk. The company must then submit compliance certificates on a quarterly basis to the exchanges until the deficiency is resolved.

Who is responsible for entering data into the SDD?

While the Compliance Officer oversees the system, the primary responsibility for making entries lies with the Designated Persons (DPs) who are sharing the information. This ensures that the record is created in real-time by those directly involved in the information flow.

How long must SDD records be preserved by a company?

According to SEBI PIT Regulation 3(6), the structured digital database must be maintained and preserved for a minimum period of 8 years after the completion of the relevant transaction or event to which the information pertains.

Educational and informational content only. ALFA Finder is not SEBI-registered and this is not investment advice. Verify all figures against the original exchange filing before acting on them.
SEBI PIT Corporate Governance Insider Trading Stock Market Regulations Indian Investing